GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,226
Erlang
31
GitHub Actions
19
Go
1,991
Maven
5,000+
npm
3,708
NuGet
661
pip
3,341
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
68 advisories
Filter by severity
Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`
High
CVE-2021-37650
was published
for
tensorflow
(pip)
Aug 25, 2021
Heap buffer overflow in `BandedTriangularSolve`
Low
CVE-2021-29612
was published
for
tensorflow
(pip)
May 21, 2021
Heap buffer overflow in `Transpose`
Moderate
CVE-2021-41216
was published
for
tensorflow
(pip)
Nov 10, 2021
Access to invalid memory during shape inference in `Cudnn*` ops
High
CVE-2021-41221
was published
for
tensorflow
(pip)
Nov 10, 2021
Overflow/denial of service in `tf.raw_ops.ReverseSequence`
Low
CVE-2021-29575
was published
for
tensorflow
(pip)
May 21, 2021
Heap buffer overflow in `Conv2DBackpropFilter`
Low
CVE-2021-29540
was published
for
tensorflow
(pip)
May 21, 2021
Heap buffer overflow in `Conv3DBackprop*`
Low
CVE-2021-29520
was published
for
tensorflow
(pip)
May 21, 2021
Heap buffer overflow in `RaggedBinCount`
Low
CVE-2021-29512
was published
for
tensorflow
(pip)
May 21, 2021
Django vulnerable to denial-of-service attack via the urlize() and urlizetrunc() template filters
Moderate
CVE-2024-45230
was published
for
Django
(pip)
Oct 8, 2024
concat built-in can corrupt memory in vyper
High
CVE-2024-22419
was published
for
vyper
(pip)
Jan 19, 2024
Buffer Copy without Checking Size of Input in Pillow
Critical
CVE-2020-5311
was published
for
pillow
(pip)
May 24, 2022
PCX P mode buffer overflow in Pillow
Critical
CVE-2020-5312
was published
for
Pillow
(pip)
Nov 3, 2021
Integer overflow in the bundled Brotli C library
Moderate
CVE-2020-8927
was published
for
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
(NuGet)
May 24, 2022
Arbitrary code execution in clickhouse-driver
Critical
CVE-2020-26759
was published
for
clickhouse-driver
(pip)
Apr 7, 2021
Buffer Overflow vulnerability in osrg gobgp
High
CVE-2023-46565
was published
for
github.com/osrg/gobgp/v3
(Go)
Apr 29, 2024
zerovec-derive incorrectly uses `#[repr(packed)]`
Moderate
GHSA-74r5-g7vc-j2v2
was published
for
zerovec-derive
(Rust)
Jul 8, 2024
zerovec incorrectly uses `#[repr(packed)]`
Moderate
GHSA-xrv3-jmcp-374j
was published
for
zerovec
(Rust)
Jul 8, 2024
StringIO buffer overread vulnerability
Critical
CVE-2024-27280
was published
for
stringio
(RubyGems)
Mar 25, 2024
ProTip!
Advisories are also available from the
GraphQL API